Historien er egentlig nogle dage gammel, så det undrer mig lidt at
den ikke allerede har været oppe at vende i gruppen. (Måske har jeg
blot overset den)
Anyway:
Folk spørger ofte hvorfor nogle af os siger, at Personal Firewalls
er noget skrammel som man normalt bør holde sig fra. Svaret er
altid, at hvis man ikke specifikt har brug for en sådan, så er det
bare endnu et "point of failure" som man derfor bør undgå.
Problemet er desværre, at mange ikke tror det er en reel bekymring.
En Personal Firewall er jo et sikkerhedsprodukt, så man forledes til
at mene at det ikke kan have sikkerhedsfejl.
Desværre forholder det sig ikke sådan. Stort set alle produkter
oplever på det ene eller det andet tidspunkt at blive ramt af
alvorlige sikkerhedsfejl. Denne gang skete det for BlackICE
Defender. Næste gang sker det måske for ZA eller Tiny eller en af de
andre.
Case in point:
[snippet fra
http://www.iss.net/security_center/alerts/advise109.php]
Internet Security Systems Security Alert
February 4, 2002
Last Revised: February 8, 2002
DoS and Potential Overflow Vulnerability in BlackICE Products
Synopsis:
ISS X-Force is aware of a denial of service vulnerability that may
allow remote attackers to crash or disrupt affected versions of
BlackICE Defender and BlackICE Agent desktop firewall/intrusion
protection products, and affected versions of RealSecure Server
Sensor. X-Force has learned that it may be possible for remote
attackers to exploit this vulnerability to execute arbitrary code on
targeted computers.
Description:
Affected versions of BlackICE Defender, BlackICE Agent, and
RealSecure Server Sensor running on Windows 2000 or Windows XP can
be remotely crashed using a modified ping flood attack. The
vulnerability is caused by a flaw in the routines used for capturing
transmitted packets. Memory can be overwritten in such a manner that
may cause the engine to crash or to behave in an unpredictable
manner. It may be possible for attackers to control which areas of
memory are overwritten, leading to the execution of arbitrary code.
--
Niels Callesøe - nørd light
pfy[at]nntp.dk -
http://www.pcpower.dk/disclaimer.php
"Again and again they struck him on the head with a
patch cable and spat upon him." - Book of THOL, verses